Using machine learning to classify DOS/DDOS attacks
M.S. Kavetskyi, Олександр Сєвєрінов, R.Y. Gvozdov, Anton Smirnov · Radiotekhnika · 2024
The relevance of this work is manifested in the need to detect and counteract DOS/DDOS attacks, which pose a serious threat to modern information systems. These cyberattacks lead to significant economic losses and disruptions in the operation of network services. The aim of the work is to confirm the hypothesis that the decision tree method performs better for detecting DOS/DDOS attacks under certain conditions. A comparison of decision tree methods with other machine learning methods (RF, SVM, KNN, ANN, NB, SGBoost) was conducted based on the CSICIDS2017 dataset. Decision trees have shown significant improvements in attack detection accuracy through optimal hyperparameter tuning and dataset selection.